CVE-2025-36940
8.8Google · Android (Fuchsia)
A use after free vulnerability in the Fuchsia zircon kernel pager proxy allows an authenticated attacker to achieve privilege escalation from userspace to kernel.
Executive summary
A high severity use after free vulnerability in the Google Android Fuchsia kernel allows local attackers to escalate privileges to the kernel level.
Vulnerability
The vulnerability is a use after free flaw within the zircon kernel pager proxy, which requires low privileges to execute. An attacker who has already established a presence on the system can leverage this flaw to gain unauthorized kernel level access.
Business impact
Successful exploitation of this vulnerability permits an attacker to bypass standard security boundaries and execute arbitrary code with kernel level permissions. Given the CVSS score of 8.8, this poses a severe risk to system integrity and confidentiality, as it effectively renders the host operating system compromised and allows for total control by an unauthorized user.
Remediation
Immediate Action: Update the affected Google Android Fuchsia installation to the version provided by the vendor in their official security documentation.
Proactive Monitoring: Monitor system logs for unexpected crashes or kernel panics that may indicate an attempt to trigger the use after free condition.
Compensating Controls: Enforce strict least privilege policies for all userspace applications to limit the potential starting point for an escalation attempt.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The severity of this privilege escalation vulnerability warrants immediate attention. Administrators should verify the current version of the Fuchsia kernel and apply the vendor provided patch as soon as possible to prevent potential unauthorized kernel access.